2 * lxc: linux Container library
4 * Copyright © 2013 Oracle.
7 * Dwight Engen <dwight.engen@oracle.com>
9 * This library is free software; you can redistribute it and/or
10 * modify it under the terms of the GNU Lesser General Public
11 * License as published by the Free Software Foundation; either
12 * version 2.1 of the License, or (at your option) any later version.
14 * This library is distributed in the hope that it will be useful,
15 * but WITHOUT ANY WARRANTY; without even the implied warranty of
16 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
17 * Lesser General Public License for more details.
19 * You should have received a copy of the GNU Lesser General Public
20 * License along with this library; if not, write to the Free Software
21 * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA
26 #include <sys/types.h>
28 #include <selinux/selinux.h>
34 #define DEFAULT_LABEL "unconfined_t"
36 lxc_log_define(lxc_lsm_selinux
, lxc
);
39 * selinux_process_label_get: Get SELinux context of a process
41 * @pid : the pid to get, or 0 for self
43 * Returns the context of the given pid. The caller must free()
44 * the returned string.
46 * Note that this relies on /proc being available.
48 static char *selinux_process_label_get(pid_t pid
)
50 security_context_t ctx
;
53 if (getpidcon_raw(pid
, &ctx
) < 0) {
54 SYSERROR("failed to get SELinux context for pid %d", pid
);
57 label
= strdup((char *)ctx
);
63 * selinux_process_label_set: Set SELinux context of a process
65 * @label : label string
66 * @conf : the container configuration to use @label is NULL
67 * @default : use the default context if label is NULL
68 * @on_exec : the new context will take effect on exec(2) not immediately
70 * Returns 0 on success, < 0 on failure
72 * Notes: This relies on /proc being available.
74 static int selinux_process_label_set(const char *inlabel
, struct lxc_conf
*conf
,
75 int use_default
, int on_exec
)
77 const char *label
= inlabel
? inlabel
: conf
->lsm_se_context
;
80 label
= DEFAULT_LABEL
;
84 if (!strcmp(label
, "unconfined_t"))
88 if (setexeccon_raw((char *)label
) < 0) {
89 SYSERROR("failed to set new SELinux exec context %s", label
);
93 if (setcon_raw((char *)label
) < 0) {
94 SYSERROR("failed to set new SELinux context %s", label
);
99 INFO("changed SELinux%s context to %s", on_exec
? " exec" : "", label
);
103 static struct lsm_drv selinux_drv
= {
105 .enabled
= is_selinux_enabled
,
106 .process_label_get
= selinux_process_label_get
,
107 .process_label_set
= selinux_process_label_set
,
110 struct lsm_drv
*lsm_selinux_drv_init(void)
112 if (!is_selinux_enabled())